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Top Stories 

• Bollinger Shipyards will pay the U.S. $8.5 million December 9 to settle claims that the 
company falsely misrepresented the longitudinal strength of patrol boats it delivered to the 
U.S. Coast Guard. - U.S. Department of Justice (See item 4) 

• Heavy storms across Seattle and Oregon December 8 closed multiple roadways, prompted 
school closures, killed 2 people, and left approximately 63,000 customers without power. - 
Reuters (See item 6) 

• Officials approved the production of Kanuma, a drug used to treat patients with lysosomal 
acid lipase (LAL) deficiency December 8, through genetically engineered chickens. - U.S. 
Food and Drug Administration (See item 20) 

• Wyndham Worldwide Corp. agreed to settle charges December 9 alleging that it failed to 
properly safeguard information on 619,000 customers following 3 data breaches that 
resulted in more than $10.6 mi llion in fraudulent charges. - Reuters (See item 31 ) 




Fast Jump Menu 



PRODUCTION INDUSTRIES 


SERVICE INDUSTRIES 


• Energy 


• Financial Services 


• Chemical 


• Transportation Systems 


• Nuclear Reactors, Materials, and Waste 


• Information Technology 


• Critical Manufacturing 


• Communications 


• Defense Industrial Base 


• Commercial Facilities 


• Dams 


FEDERAL and STATE 


SUSTENANCE and HEALTH 


• Government Facilities 


• Food and Agriculture 


• Emergency Services 


• Water and Wastewater Systems 




• Healthcare and Public Health 





Energy Sector 

1. December 9, KNSD 39 San Diego - (California) Cal/OSHA fines company $58K for 
explosion that injured employees. The California Division of Occupational Safety 
and Health cited Quantum Energy Storage Corporation with 16 health and safety 
violations December 9 including failure to minimizing hazards where employees 
worked, following a June 10 incident at the company’s Poway warehouse where an 

1 1,000-pound flywheel caused an explosion that left 4 employees injured. Proposed 
fines total $58,025. 

Source: http://www.nbcsandiego.com/news/local/CalOSHA-Cites-Company-58K-for- 
Explosion-That-Iniured-Employees-361368671.html 

2. December 8, U.S. Department of Labor - (Florida) OSHA reaches settlement with 
Blue Rhino in 2013 propane explosion that severely injured 6 workers at Taveras, 
Florida, tank facility. The Occupational Safety and Health Administration reached a 
settlement with Ferrellgas LP doing business as Blue Rhino Corporation December 7 
resolving 9 serious and 6 other-than-serious citations following a July 2013 incident 
where propane vapor was ignited from a forklift that was not explosion proof, leaving 
10 workers injured. Proposed penalties $52,000. 

Source: 

https://www.osha.gov/pls/oshaweb/owadisp.show document?p table=NEWS RELEA 
SES&p id=29208 

For additional stories, see items 6 and 23 

Chemical Industry Sector 

Nothing to report 

Nuclear Reactors, Materials, and Waste Sector 

Nothing to report 

Critical Manufacturing Sector 

3. December 9, U.S. Consumer Product Safety Commission - (National) Easier Electric 
recalls transformers due to fire, shock hazards. Basler Electric Company issued a 
nationwide recall December 9 for approximately 1 1,900 Basler Class 2 electric 
transformers due to fire and electrical shock hazards prompted by a potential circuit 
breaker trip failure. The products were sold from September 2014 to November 2014 to 
various manufacturers and distributors. 

Source: http://www.cpsc.gov/en/Recalls/Recall-Alerts/2016/Basler-Electric-Recalls- 
Transformers/ 



Defense Industrial Base Sector 

4. December 9, U.S. Department of Justice - (National) Bollinger Shipyards agrees to 
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settle False Claims Act suit. The U.S. Department of Justice announced December 9 
that Louisiana-based Bollinger Shipyards will pay the U.S. $8.5 million and release 
contract claims to settle False Claims Act violations after an investigation found that 
the company falsely misrepresented the longitudinal strength of patrol boats it delivered 
to the U.S. Coast Guard that resulted in the boats buckling and failing. 

Source: http://www.iustice.gov/opa/pr/bollinger-shipyards-agrees-settle-false-claims- 
act-suit 



Financial Services Sector 

5. December 9, KUTV 2 Salt Lake City - (Utah) Police looking for ‘bucket list bandit’ 
involved in Salt Lake Valley robberies. Unified Police are searching for a suspect 
December 9 believed to be connected to a string of robberies in the Salt Lake County 
area which include two hotels in addition to a Wells Fargo bank branch, a US Bank 
branch, and an Americas First Credit Union branch. Authorities believe the suspect is 
armed. 

Source: http://kutv.com/news/local/police-looking-for-bucket-list-bandit-who-has- 
robbed-banks-around-the-salt-lake-valley 

Transportation Systems Sector 

6. December 10, Reuters - (Oregon; Washington) Two dead, thousands without power 
after US Pacific Northwest storms. Heavy storms across Seattle and Oregon triggered 
mudslides and flooding December 8 which closed multiple roadways and interstate 
highways until at least December 10, prompted school closures for 3 consecutive days, 
killed 2 people, and left approximately 26,000 customers in Portland and 37,000 
customers in Seattle without power. 

Source: http://www.cnbc.com/2015/12/10/two-dead-thousands-without-power-after-us- 
pacific-northwest-storms.html 

7. December 10, WBRC 6 Birmingham - (Alabama) 2 northbound lanes open on I- 
20/59 near Arkadelphia Road after hazmat situation. Northbound lanes of Interstate 
20/59 in Birmingham were shut down for several hours overnight December 9 - 
December 10 while HAZMAT crews cleared a chemical spill from an overturned semi- 
truck that caught fire and forced the evacuation of East Thomas and College Hills 
communities. 

Source: http://www.kltv.com/storv/30710363/northbound-lanes-still-closed-after- 
hazmat-situation-on-i-2059-near-arkadelphia-road-exit 

8. December 10, U.S. Environmental Protection Agency - (California) U.S. EPA md 
customs joint operations at California Ports results in illegal vehicles and engines 
seized or turned back at border. The U.S. Environmental Protection Agency and U.S. 
Customs and Border Protection charged 8 companies a total of $94,700 in fines 
December 9 after the companies allegedly violated the Federal Clean Air Act or 
Federal Insecticide, Fungicide, and Rodenticide Act by importing foreign-made 
vehicles and equipment without proper emission controls, and by importing illegal 
pesticides at the ports of Eos Angeles, Fong Beach, and Oakland. More than 1,394 



items were seized, exported, or destroyed as part of the agency’s attempts to uphold the 
Clean Air Act. 

Source: 

http://vosemite.epa.gOv/opa/admpress.nsf/0/D4601695D9FlAE7A85257F160063DE13 

9. December 10, WINK 11 Fort Myers - (Florida) Pregnant woman dies after auto- 
pedestrian crash. Southbound lanes of U.S. 41 in Fort Myers were shut down for 
several hours December 8 after a pedestrian was killed after being hit while crossing 
the road. 

Source: http://www.winknews.com/2015/12/10/pregnant-woman-dies-after-auto- 
pedestrian-crash/ 

For additional stories, see items 4 and 30 

Food and Agriculture Sector 

10. December 9, U.S. Food and Drug Administration - (National) The Morrison Milling 
Company voluntary and precautionary recall of corn products. The U.S. Food and 
Drug Administration announced December 9 that Texas-based Morrison Milling 
Company issued a voluntary recall for several types of its com products after the 
company’s quality department discovered that the products may contain pieces of 
flexible metal mesh due to a faulty screen at its Denton production facility. Products 
were distributed to retail stores in several Southwestern States. 

Source: http://www.fda.gov/Safety/Recalls/ucm476512.htm 

11. December 9, U.S. Food and Drug Administration - (National) Lucy’s Weight Loss 
System issues voluntary nationwide recall of Pink Bikini dietary supplement due 
to undeclared diclofenac. The U.S. Food and Drug Administration announced 
December 9 that Texas-based Fucy’s Weight Foss System issued a voluntary, 
nationwide recall for all lots of its Pink Bikini White powder Capsules, 30 white after 
testing discovered the presence of diclofenac, a nonsteroidal anti-inflammatory drug. 
Products were distributed through Internet sales via the company’s Web site and at one 
retail location. 

Source: http://www.fda.gov/Safety/Recalls/ucm476494.htm 

12. December 9, Seattle Times - (Washington) Food vendors open again after Russell 
Tower outbreak. Officials announced that food vendors at the Russell Investments 
Center in Seattle were allowed to reopen December 9 after the building was cleaned 
following a norovirus outbreak that sickened over 200 people who attended a catered 
party at the building December 1 . Health officials are still investigating the cause of the 
outbreak. 

Source: http://www.seattletimes.com/seattle-news/health/food-vendors-open-again- 
after-russell-tower-outbreak/ 

13. December 9, USA Today - (Massachusetts) Norovirus strikes 120 Boston College 
students who ate at Chipotle. Officials reported December 9 that at least 120 Boston 
College students and others from the surrounding community were sickened by 



norovirus after eating at a Boston area Chipotle Mexican Grill, Inc. restaurant that 
remained closed for extensive cleaning and a full sanitization. The Massachusetts 
school issued a health alert and stated that it would close self-serve cafeteria sections 
and thoroughly clean common areas. 

Source: http://www.usatodav.com/storv/news/2015/12/09/norovirus-boston-college- 
outbreak/77046408/ 

Water and Wastewater Systems Sector 

14. December 9, Sioux City Journal - (Nebraska) Corps awards $1.75M bid for habitat 
repairs at Ponca State Park. The Western Contracting Corporation of Sioux City 
received a $1.75 million contract from the U.S. Army Corps of Engineers December 9 
to complete repairs on a backwater site along the Mississippi river at Ponca State Park 
located in Omaha, Nebraska, which is expected to finish by the end of 2016. 

Source: http://siouxcitviournal.com/news/local/corps-awards-m-bid-for-habitat-repairs- 
at-ponca-state/article e8aa2a5c-193a-5e4d-bl6e-a08fd69fd005.html 

15. December 9, KRCR 7 Redding/ Chico; Associated Press - (California) Water 
contamination examined after toxic discovery. Officials closed Livermore’s Lake 
Del Valle December 9 after preliminary testing revealed that the water’s toxicity levels 
exceeded the threshold set by park authorities following a park employee’s discovery 
of blue-green algae December 7. 

Source: http://www.krcrtv.com/news/local/water-contamination-examined-after-toxic- 
discovery/36890142 

Lor another story, see item 23 

Healthcare and Public Health Sector 

16. December 9, Minneapolis Star Tribune - (Minnesota) State is fined $63K for safety 
violations at security hospital in St. Peter. The Minnesota Occupational Safety and 
Health Administration issued a $63,000 fine to the Minnesota Department of Human 
Services December 9 for failing to protect workers at the St. Peter psychiatric hospital 
from violent assaults by patients following 9 incidents that occurred between May and 
July. The hospital has implemented additional security measures including the 
installation of new security cameras and intensified staff training, among other 
measures. 

Source: http://www.startribune.com/state-mental-hospital-fined-63-00Q-for- workplace- 
safety- violations/36 1297781/ 

17. December 9, WITI 6 Milwaukee - (Wisconsin) No injuries after chemical spill forces 
evacuation at Bradshaw Medical in Kenosha. Employees at Bradshaw Medical in 
Kenosha were evacuated for approximately 3 hours December 9 after roughly 20 
gallons of nitric acid spilled from a 55-gallon drum and created a vapor cloud. The 
chemical reacted violently when it was poured into a barrel that was thought to be 
clean. 

Source: http://fox6now.com/2015/12/09/developing-hazmat-team-called-out-to- 
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bradshaw-medical-in-kenosha/ 



18. December 9, WTAE 4 Pittsburgh - (Pennsylvania) Family counselor charged with 
billing insurance $600,000 for fake office visits. A Pennsylvania family counselor 
was charged December 9 for allegedly billing BlueCross/Blue Shield $601,000 for 
counseling sessions that never occurred. The counselor conducted fewer than 2,000 
sessions and billed the insurance company for more than 9,700 office visits from 2011 
-2015. 

Source: http://www.wtae.com/news/family-counselor-charged-with-billing-insurance- 
600000-for-fake-office- visits/36876696 



19. December 8, Maine Public Broadcasting News - (Maine) Information for some 

patients exposed in MaineGeneral hack. MaineGeneral Health announced December 
8 that some patient and employee data was available on an external Web site with the 
proper login credentials following a breach of its computer network. The hospital 
continues to investigate the cyberattack, which is connected to an another ongoing 
investigation. 

Source: http://news.mpbn.net/post/information-some-patients-exposed-mainegeneral- 
hack 



20. December 8, U.S. Food and Drug Administration - (National) FDA approves first 
drug to treat rare enzyme disorder in pediatric and adults patients. The U.S. Food 
and Drug Administration approved the production of Kanuma (sebelipase alfa) a drug 
used to treat patients with the disease lysosomal acid lipase (LAL) deficiency 
December 8. The drug gained approval to be constructed in chickens that are 
genetically engineered to produce a recombinant form of human lysosomal acid lipase 
(rhLAL) protein in their egg whites. 

Source: 

http://www.fda.gov/NewsEvents/Newsroom/PressAnnouncements/ucm476013.htm 
For additional stories, see items 12 and 13 

Government Facilities Sector 

21. December 9, WPTZ 5 Plattsburgh - (Vermont) Charlotte school students dismissed 
after boiler leak. Students were evacuated from Charlotte Central School in Vermont 
and classes were dismissed December 9 after maintenance staff discovered that a leak 
in the school’s boiler spilled about 50 - 100 gallons of glycol and circulated throughout 
the building. Classes were scheduled to resume December 10 following cleanup. 
Source: http://www.wptz.com/news/charlotte-school-evacuated-after-hazmat- 
situation/36876434 

22. December 9, WJTV 12 Jackson - (Mississippi) Students charged in bomb threat at 
Warren Central Jr. High. Authorities arrested two Warren Central Jr. High School 
students December 9 after the Vicksburg school was evacuated following the discovery 
of a device in a backpack. A bomb squad safely detonated the device and investigators 
charged the students. 
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Source: http://whlt.com/2015/12/Q9/students-charged-in-bomb-threat-at-warren- 
central-jr-high/ 



23. December 8, KGBT 4 Harlingen - (Texas) Roughly 2,000 gallons of oil spills into 
Brownsville drainage ditch. About 2,000 gallons of spilled oil reached a drainage 
ditch following a spill of an estimated 2,900 gallons of oil from a tank at the City of 
Brownsville Public Works Department yard December 8. Workers contained the spill 
and crews worked to clean up the oil. 

Source: http://vallevcentral.com/news/local/brownsville-public-works-oil-spill- 
december-2015-canal-ditch-oily-substance-leak 



For additional stories, see items 4 and 6 

Emergency Services Sector 

Nothing to report 

Information Technology Sector 

24. December 10, SecurityWeek - (International) Many Cisco products plagued by 
deserializations flaws. Cisco Systems reported that it is investigating which of its 
products are affected by the Java deserialization vulnerability that can be exploited for 
remote code execution (RCE) via the Apache Commons Collections library due to the 
failure of developers to ensure that untrusted serialized data is not accepted for 
deserialization. Cisco will release software updates addressing the flaw. 

Source: http://www.securitvweek.com/manv-cisco-products-plagued-deserialization- 
flaws 



25. December 10, SecurityWeek - (International) Google launches Data Loss Prevention 
(DLP) for Gmail. Google announced its new feature, Data Loss Prevention (DLP) for 
Gmail will help administrators enforce DLP policies and will automatically take action 
based on predefined content detectors in email text and attachment types, including 
documents, presentations, and spreadsheets to ensure that sensitive information cannot 
be exposed to unauthorized viewers. The feature is available for Google Apps for Work 
Unlimited customers only. 

Source: http://www.securitvweek.com/google-launches-data-loss-prevention-dlp-gmail 

26. December 10, Softpedia - (International) Barbeques are now hackable thanks to 
ever-evolving technology. Two American security researchers discovered that smart 
Internet of Things (IoT) devices can be easily abused after discovering ways to 
infiltrate the BBQ Guru-owned CyberQ Wifi BBQ Control, which comes manufactured 
with Internet capabilities, via a malicious Uniform Resource Locator (URL) code 
crafted by attackers intended to deceive a CyberQ owner into opening the link via a 
simple spear phishing campaign. Once the malicious link is opened, hackers can access 
the user’s privileges and command the barbeque to alter its behavior. 

Source: http://news.softpedia.com/news/barbeques-are-now-hackable-thanks-to-ever- 
evolving-technology-4974 1 8 . shtml 
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27. December 9, SecurityWeek - (International) Google brings safe browsing to Chrome 
for Android. Google released its Safe Browsing technology in Google Play Services 
version 8.1, and Chrome for Android version 46 and above versions that will warn 
users when accessing a flagged Web site, including social engineering, phishing, and 
other malicious Web sites. 

Source: http://www.securitvweek.com/google-brings-safe-browsing-chrome-android 

28. December 9, Zero Day - (International) Microsoft warns of possible attacks after 
Xbox certificate leaked. Microsoft released an advisory stating that the private keys to 
the xboxlive.com domain were inadvertently disclosed, allowing attackers to 
impersonate Xbox users and carry out man-in-the-middle (MitM) attacks, as well as 
intercept the Web site’s secure connection to deceive users in providing their username 
and passwords to hackers. 

Source: http://www.zdnet.com/article/microsoft-warns-attacks-possible-after-xbox- 
certificate-leaked/ 



Internet Alert Dashboard 



To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT ISAC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 



Communications Sector 

Nothing to report 

Commercial Facilities Sector 

29. December 9, U.S. Department of Labor - (Ohio) Electronics recycler over-exposes 
workers to lead, fined more than $56K. The Occupational Safety and Health 
Administration cited Ohio-based Echo Environmental Waverly LLC December 8 for 
six serious and three other- than- serious health violations after a June inspection of its 
Waverly facility found that the company failed to protect employees from dangerous 
lead contamination associated with electronics recycling, among other violations. 
Proposed fines total $56,850. 

Source: 

https://www.osha.gov/pls/oshaweb/owadisp.show document?p table=NEWS RELEA 
SES&p id=29226 

30. December 10, WABC 7 New York City - (New York) Residents return to 4 buildings 
evacuated in Borough Park due to gas leak. A gas leak in Borough Park, Brooklyn, 
prompted the evacuation of four residential buildings for several hours and closed 
surrounding streets December 9 - December 10 while crews fixed the leak following 
the discovery of a large hole in a high pressure gas main. 

Source: http://abc7nv.com/news/four-buildings-evacuated-in-borough-park-due-to-gas- 
leak/1116779/ 
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31. December 9, Reuters - (New Jersey) Wyndham settles FTC data breach charges. 
Wyndham Worldwide Corp. agreed to settle charges December 9 filed by the U.S. 
Federal Trade Commission to resolve allegations that the company failed to properly 
safeguard information on 619,000 customers following 3 data breaches in which 
attackers hacked into the company’s computer system and stole customers’ payment 
card and personal information, resulting in more than $10.6 million in fraudulent 
charges. As part of the settlement, Wyndham is required to comply with a widely used 
industry standard to protect the safety of payment card information. 

Source: http://www.reuters.com/article/us-wvndham-ftc-cvbersecuritv- 
idUSKBN0TS24220151209#RHSWcQQVCPUHqTt0.97 

For additional stories, see items 5 and 12 

Dams Sector 



32. December 9, Associated Press; Press of Atlantic City - (New Jersey) Stone Harbor 

dredging on hold after 20,000-gallon spill. A dredging project in Stone Harbor, New 
Jersey, was shut down December 8 after 20,000 gallons of treated water and dredge 
spoils spilled onto a residential street December 4. Officials reported that the project 
will resume after contractors and officials find a solution to contain the water from 
going off site. 

Source: http://www.courierpostonline.com/storv/news/local/south- 
iersev/2015/12/09/stone-harbor-dredging-hold-gallon-spill/77033384/ 
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Department of Homeland Security (DHS) 

DHS Daily Open Source Infrastructure Report Contact Information 

About the reports - The DHS Daily Open Source Infrastructure Report is a daily [Monday 
through Friday] summary of open-source published information concerning significant critical 
infrastructure issues. The DHS Daily Open Source Infrastructure Report is archived for 10 days on 
the Department of Homeland Security Web site: http://www.dhs.gov/IPDailyReport 

Contact Information 

Content and Suggestions: Send mail to cikr.productfeedback@hq.dhs.gov or contact the DHS 

Daily Report Team at (703) 942-8590 

Subscribe to the Distribution List: Visit the DHS Daily Open Source Infrastructure Report and follow 

instructions to Get e-mail updates when this information changes . 

Removal from Distribution List: Send mail to support@govdeliverv.com . 



Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source 
material. 
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